scan.c 25.1 KB
Newer Older
1
/*
2 3
 * Scanning implementation
 *
4 5 6 7 8 9 10 11 12 13 14 15
 * Copyright 2003, Jouni Malinen <jkmaline@cc.hut.fi>
 * Copyright 2004, Instant802 Networks, Inc.
 * Copyright 2005, Devicescape Software, Inc.
 * Copyright 2006-2007	Jiri Benc <jbenc@suse.cz>
 * Copyright 2007, Michael Wu <flamingice@sourmilk.net>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

#include <linux/if_arp.h>
16
#include <linux/rtnetlink.h>
17 18
#include <linux/pm_qos_params.h>
#include <net/sch_generic.h>
19
#include <linux/slab.h>
20 21 22
#include <net/mac80211.h>

#include "ieee80211_i.h"
23
#include "driver-ops.h"
24
#include "mesh.h"
25 26 27

#define IEEE80211_PROBE_DELAY (HZ / 33)
#define IEEE80211_CHANNEL_TIME (HZ / 33)
28
#define IEEE80211_PASSIVE_CHANNEL_TIME (HZ / 8)
29

30
struct ieee80211_bss *
31 32 33
ieee80211_rx_bss_get(struct ieee80211_local *local, u8 *bssid, int freq,
		     u8 *ssid, u8 ssid_len)
{
34 35 36 37 38 39 40 41
	struct cfg80211_bss *cbss;

	cbss = cfg80211_get_bss(local->hw.wiphy,
				ieee80211_get_channel(local->hw.wiphy, freq),
				bssid, ssid, ssid_len, 0, 0);
	if (!cbss)
		return NULL;
	return (void *)cbss->priv;
42 43
}

44
static void ieee80211_rx_bss_free(struct cfg80211_bss *cbss)
45
{
46
	struct ieee80211_bss *bss = (void *)cbss->priv;
47 48 49 50 51 52

	kfree(bss_mesh_id(bss));
	kfree(bss_mesh_cfg(bss));
}

void ieee80211_rx_bss_put(struct ieee80211_local *local,
53
			  struct ieee80211_bss *bss)
54
{
55 56 57
	if (!bss)
		return;
	cfg80211_put_bss(container_of((void *)bss, struct cfg80211_bss, priv));
58 59
}

K
Kalle Valo 已提交
60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76
static bool is_uapsd_supported(struct ieee802_11_elems *elems)
{
	u8 qos_info;

	if (elems->wmm_info && elems->wmm_info_len == 7
	    && elems->wmm_info[5] == 1)
		qos_info = elems->wmm_info[6];
	else if (elems->wmm_param && elems->wmm_param_len == 24
		 && elems->wmm_param[5] == 1)
		qos_info = elems->wmm_param[6];
	else
		/* no valid wmm information or parameter element found */
		return false;

	return qos_info & IEEE80211_WMM_IE_AP_QOSINFO_UAPSD;
}

77
struct ieee80211_bss *
78 79 80 81 82
ieee80211_bss_info_update(struct ieee80211_local *local,
			  struct ieee80211_rx_status *rx_status,
			  struct ieee80211_mgmt *mgmt,
			  size_t len,
			  struct ieee802_11_elems *elems,
83 84
			  struct ieee80211_channel *channel,
			  bool beacon)
85
{
86
	struct cfg80211_bss *cbss;
87
	struct ieee80211_bss *bss;
88
	int clen, srlen;
89 90
	s32 signal = 0;

J
Johannes Berg 已提交
91
	if (local->hw.flags & IEEE80211_HW_SIGNAL_DBM)
92
		signal = rx_status->signal * 100;
J
Johannes Berg 已提交
93
	else if (local->hw.flags & IEEE80211_HW_SIGNAL_UNSPEC)
94 95
		signal = (rx_status->signal * 100) / local->hw.max_signal;

96 97
	cbss = cfg80211_inform_bss_frame(local->hw.wiphy, channel,
					 mgmt, len, signal, GFP_ATOMIC);
98

99
	if (!cbss)
100 101
		return NULL;

102 103
	cbss->free_priv = ieee80211_rx_bss_free;
	bss = (void *)cbss->priv;
104 105 106 107 108 109 110 111 112 113 114 115 116

	/* save the ERP value so that it is available at association time */
	if (elems->erp_info && elems->erp_info_len >= 1) {
		bss->erp_value = elems->erp_info[0];
		bss->has_erp_value = 1;
	}

	if (elems->tim) {
		struct ieee80211_tim_ie *tim_ie =
			(struct ieee80211_tim_ie *)elems->tim;
		bss->dtim_period = tim_ie->dtim_period;
	}

117 118 119 120
	/* If the beacon had no TIM IE, or it was invalid, use 1 */
	if (beacon && !bss->dtim_period)
		bss->dtim_period = 1;

121 122
	/* replace old supported rates if we get new values */
	srlen = 0;
123
	if (elems->supp_rates) {
124
		clen = IEEE80211_MAX_SUPP_RATES;
125 126
		if (clen > elems->supp_rates_len)
			clen = elems->supp_rates_len;
127 128
		memcpy(bss->supp_rates, elems->supp_rates, clen);
		srlen += clen;
129 130
	}
	if (elems->ext_supp_rates) {
131
		clen = IEEE80211_MAX_SUPP_RATES - srlen;
132 133
		if (clen > elems->ext_supp_rates_len)
			clen = elems->ext_supp_rates_len;
134 135
		memcpy(bss->supp_rates + srlen, elems->ext_supp_rates, clen);
		srlen += clen;
136
	}
137 138
	if (srlen)
		bss->supp_rates_len = srlen;
139 140

	bss->wmm_used = elems->wmm_param || elems->wmm_info;
K
Kalle Valo 已提交
141
	bss->uapsd_supported = is_uapsd_supported(elems);
142 143 144 145 146 147

	if (!beacon)
		bss->last_probe_resp = jiffies;

	return bss;
}
148

149
ieee80211_rx_result
150
ieee80211_scan_rx(struct ieee80211_sub_if_data *sdata, struct sk_buff *skb)
151
{
152
	struct ieee80211_rx_status *rx_status = IEEE80211_SKB_RXCB(skb);
153
	struct ieee80211_mgmt *mgmt;
154
	struct ieee80211_bss *bss;
155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172
	u8 *elements;
	struct ieee80211_channel *channel;
	size_t baselen;
	int freq;
	__le16 fc;
	bool presp, beacon = false;
	struct ieee802_11_elems elems;

	if (skb->len < 2)
		return RX_DROP_UNUSABLE;

	mgmt = (struct ieee80211_mgmt *) skb->data;
	fc = mgmt->frame_control;

	if (ieee80211_is_ctl(fc))
		return RX_CONTINUE;

	if (skb->len < 24)
173
		return RX_CONTINUE;
174 175 176 177

	presp = ieee80211_is_probe_resp(fc);
	if (presp) {
		/* ignore ProbeResp to foreign address */
178
		if (memcmp(mgmt->da, sdata->vif.addr, ETH_ALEN))
179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198
			return RX_DROP_MONITOR;

		presp = true;
		elements = mgmt->u.probe_resp.variable;
		baselen = offsetof(struct ieee80211_mgmt, u.probe_resp.variable);
	} else {
		beacon = ieee80211_is_beacon(fc);
		baselen = offsetof(struct ieee80211_mgmt, u.beacon.variable);
		elements = mgmt->u.beacon.variable;
	}

	if (!presp && !beacon)
		return RX_CONTINUE;

	if (baselen > skb->len)
		return RX_DROP_MONITOR;

	ieee802_11_parse_elems(elements, skb->len - baselen, &elems);

	if (elems.ds_params && elems.ds_params_len == 1)
199 200
		freq = ieee80211_channel_to_frequency(elems.ds_params[0],
						      rx_status->band);
201 202 203 204 205 206 207 208 209 210
	else
		freq = rx_status->freq;

	channel = ieee80211_get_channel(sdata->local->hw.wiphy, freq);

	if (!channel || channel->flags & IEEE80211_CHAN_DISABLED)
		return RX_DROP_MONITOR;

	bss = ieee80211_bss_info_update(sdata->local, rx_status,
					mgmt, skb->len, &elems,
211
					channel, beacon);
212 213
	if (bss)
		ieee80211_rx_bss_put(sdata->local, bss);
214

215 216 217 218 219 220 221 222
	/* If we are on-operating-channel, and this packet is for the
	 * current channel, pass the pkt on up the stack so that
	 * the rest of the stack can make use of it.
	 */
	if (ieee80211_cfg_on_oper_channel(sdata->local)
	    && (channel == sdata->local->oper_channel))
		return RX_CONTINUE;

223 224 225 226
	dev_kfree_skb(skb);
	return RX_QUEUED;
}

227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253
/* return false if no more work */
static bool ieee80211_prep_hw_scan(struct ieee80211_local *local)
{
	struct cfg80211_scan_request *req = local->scan_req;
	enum ieee80211_band band;
	int i, ielen, n_chans;

	do {
		if (local->hw_scan_band == IEEE80211_NUM_BANDS)
			return false;

		band = local->hw_scan_band;
		n_chans = 0;
		for (i = 0; i < req->n_channels; i++) {
			if (req->channels[i]->band == band) {
				local->hw_scan_req->channels[n_chans] =
							req->channels[i];
				n_chans++;
			}
		}

		local->hw_scan_band++;
	} while (!n_chans);

	local->hw_scan_req->n_channels = n_chans;

	ielen = ieee80211_build_preq_ies(local, (u8 *)local->hw_scan_req->ie,
254 255
					 req->ie, req->ie_len, band, (u32) -1,
					 0);
256 257 258 259 260
	local->hw_scan_req->ie_len = ielen;

	return true;
}

261
static void __ieee80211_scan_completed(struct ieee80211_hw *hw, bool aborted,
262
				       bool was_hw_scan)
263 264
{
	struct ieee80211_local *local = hw_to_local(hw);
265 266
	bool on_oper_chan;
	bool enable_beacons = false;
267

268
	lockdep_assert_held(&local->mtx);
269

270 271 272 273 274 275 276 277
	/*
	 * It's ok to abort a not-yet-running scan (that
	 * we have one at all will be verified by checking
	 * local->scan_req next), but not to complete it
	 * successfully.
	 */
	if (WARN_ON(!local->scanning && !aborted))
		aborted = true;
278

279
	if (WARN_ON(!local->scan_req))
280
		return;
281

282
	if (was_hw_scan && !aborted && ieee80211_prep_hw_scan(local)) {
283 284
		int rc = drv_hw_scan(local, local->scan_sdata, local->hw_scan_req);
		if (rc == 0)
285
			return;
286 287 288 289
	}

	kfree(local->hw_scan_req);
	local->hw_scan_req = NULL;
290

291
	if (local->scan_req != local->int_scan_req)
292 293
		cfg80211_scan_done(local->scan_req, aborted);
	local->scan_req = NULL;
294
	local->scan_sdata = NULL;
295

296
	local->scanning = 0;
J
Johannes Berg 已提交
297
	local->scan_channel = NULL;
298

299 300
	on_oper_chan = ieee80211_cfg_on_oper_channel(local);

301
	if (was_hw_scan || !on_oper_chan)
302
		ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_CHANNEL);
303
	else
304 305
		/* Set power back to normal operating levels. */
		ieee80211_hw_config(local, 0);
306

307
	if (!was_hw_scan) {
308
		bool on_oper_chan2;
309 310
		ieee80211_configure_filter(local);
		drv_sw_scan_complete(local);
311 312 313 314 315 316 317
		on_oper_chan2 = ieee80211_cfg_on_oper_channel(local);
		/* We should always be on-channel at this point. */
		WARN_ON(!on_oper_chan2);
		if (on_oper_chan2 && (on_oper_chan != on_oper_chan2))
			enable_beacons = true;

		ieee80211_offchannel_return(local, enable_beacons, true);
318
	}
319

J
Johannes Berg 已提交
320
	ieee80211_recalc_idle(local);
321

322
	ieee80211_mlme_notify_scan_completed(local);
323
	ieee80211_ibss_notify_scan_completed(local);
324
	ieee80211_mesh_notify_scan_completed(local);
J
Johannes Berg 已提交
325
	ieee80211_queue_work(&local->hw, &local->work_work);
326
}
327 328 329 330 331 332 333 334 335 336 337 338

void ieee80211_scan_completed(struct ieee80211_hw *hw, bool aborted)
{
	struct ieee80211_local *local = hw_to_local(hw);

	trace_api_scan_completed(local, aborted);

	set_bit(SCAN_COMPLETED, &local->scanning);
	if (aborted)
		set_bit(SCAN_ABORTED, &local->scanning);
	ieee80211_queue_delayed_work(&local->hw, &local->scan_work, 0);
}
339 340
EXPORT_SYMBOL(ieee80211_scan_completed);

341 342 343 344 345 346 347 348 349 350 351 352 353 354 355
static int ieee80211_start_sw_scan(struct ieee80211_local *local)
{
	/*
	 * Hardware/driver doesn't support hw_scan, so use software
	 * scanning instead. First send a nullfunc frame with power save
	 * bit on so that AP will buffer the frames for us while we are not
	 * listening, then send probe requests to each channel and wait for
	 * the responses. After all channels are scanned, tune back to the
	 * original channel and send a nullfunc frame with power save bit
	 * off to trigger the AP to send us all the buffered frames.
	 *
	 * Note that while local->sw_scanning is true everything else but
	 * nullfunc frames and probe requests will be dropped in
	 * ieee80211_tx_h_check_assoc().
	 */
356
	drv_sw_scan_start(local);
357

358
	local->leave_oper_channel_time = 0;
359
	local->next_scan_state = SCAN_DECISION;
360 361
	local->scan_channel_idx = 0;

362 363 364 365 366
	/* We always want to use off-channel PS, even if we
	 * are not really leaving oper-channel.  Don't
	 * tell the AP though, as long as we are on-channel.
	 */
	ieee80211_offchannel_enable_all_ps(local, false);
367

368
	ieee80211_configure_filter(local);
369

370 371 372
	/* We need to set power level at maximum rate for scanning. */
	ieee80211_hw_config(local, 0);

373 374 375
	ieee80211_queue_delayed_work(&local->hw,
				     &local->scan_work,
				     IEEE80211_CHANNEL_TIME);
376 377 378 379 380 381 382 383 384 385 386

	return 0;
}


static int __ieee80211_start_scan(struct ieee80211_sub_if_data *sdata,
				  struct cfg80211_scan_request *req)
{
	struct ieee80211_local *local = sdata->local;
	int rc;

387 388
	lockdep_assert_held(&local->mtx);

389 390 391
	if (local->scan_req)
		return -EBUSY;

392 393
	if (!list_empty(&local->work_list)) {
		/* wait for the work to finish/time out */
394 395 396 397 398
		local->scan_req = req;
		local->scan_sdata = sdata;
		return 0;
	}

399 400 401
	if (local->ops->hw_scan) {
		u8 *ies;

402 403 404 405 406 407
		local->hw_scan_req = kmalloc(
				sizeof(*local->hw_scan_req) +
				req->n_channels * sizeof(req->channels[0]) +
				2 + IEEE80211_MAX_SSID_LEN + local->scan_ies_len +
				req->ie_len, GFP_KERNEL);
		if (!local->hw_scan_req)
408 409
			return -ENOMEM;

410 411 412 413 414 415 416 417
		local->hw_scan_req->ssids = req->ssids;
		local->hw_scan_req->n_ssids = req->n_ssids;
		ies = (u8 *)local->hw_scan_req +
			sizeof(*local->hw_scan_req) +
			req->n_channels * sizeof(req->channels[0]);
		local->hw_scan_req->ie = ies;

		local->hw_scan_band = 0;
418 419 420 421 422 423 424 425

		/*
		 * After allocating local->hw_scan_req, we must
		 * go through until ieee80211_prep_hw_scan(), so
		 * anything that might be changed here and leave
		 * this function early must not go after this
		 * allocation.
		 */
426 427 428 429 430 431
	}

	local->scan_req = req;
	local->scan_sdata = sdata;

	if (local->ops->hw_scan)
432
		__set_bit(SCAN_HW_SCANNING, &local->scanning);
433
	else
434
		__set_bit(SCAN_SW_SCANNING, &local->scanning);
435

J
Johannes Berg 已提交
436
	ieee80211_recalc_idle(local);
437

438 439
	if (local->ops->hw_scan) {
		WARN_ON(!ieee80211_prep_hw_scan(local));
440
		rc = drv_hw_scan(local, sdata, local->hw_scan_req);
441
	} else
442 443 444
		rc = ieee80211_start_sw_scan(local);

	if (rc) {
445 446
		kfree(local->hw_scan_req);
		local->hw_scan_req = NULL;
447
		local->scanning = 0;
448

J
Johannes Berg 已提交
449 450
		ieee80211_recalc_idle(local);

451 452 453 454 455 456 457
		local->scan_req = NULL;
		local->scan_sdata = NULL;
	}

	return rc;
}

458 459 460 461 462 463 464 465 466 467 468 469
static unsigned long
ieee80211_scan_get_channel_time(struct ieee80211_channel *chan)
{
	/*
	 * TODO: channel switching also consumes quite some time,
	 * add that delay as well to get a better estimation
	 */
	if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
		return IEEE80211_PASSIVE_CHANNEL_TIME;
	return IEEE80211_PROBE_DELAY + IEEE80211_CHANNEL_TIME;
}

470 471
static void ieee80211_scan_state_decision(struct ieee80211_local *local,
					  unsigned long *next_delay)
H
Helmut Schaa 已提交
472
{
473
	bool associated = false;
474 475 476 477
	bool tx_empty = true;
	bool bad_latency;
	bool listen_int_exceeded;
	unsigned long min_beacon_int = 0;
478
	struct ieee80211_sub_if_data *sdata;
479
	struct ieee80211_channel *next_chan;
480

481 482 483 484 485
	/*
	 * check if at least one STA interface is associated,
	 * check if at least one STA interface has pending tx frames
	 * and grab the lowest used beacon interval
	 */
486 487
	mutex_lock(&local->iflist_mtx);
	list_for_each_entry(sdata, &local->interfaces, list) {
488
		if (!ieee80211_sdata_running(sdata))
489 490 491 492 493
			continue;

		if (sdata->vif.type == NL80211_IFTYPE_STATION) {
			if (sdata->u.mgd.associated) {
				associated = true;
494 495 496 497 498 499 500 501 502 503

				if (sdata->vif.bss_conf.beacon_int <
				    min_beacon_int || min_beacon_int == 0)
					min_beacon_int =
						sdata->vif.bss_conf.beacon_int;

				if (!qdisc_all_tx_empty(sdata->dev)) {
					tx_empty = false;
					break;
				}
504 505 506 507 508
			}
		}
	}
	mutex_unlock(&local->iflist_mtx);

509 510 511 512
	next_chan = local->scan_req->channels[local->scan_channel_idx];

	if (ieee80211_cfg_on_oper_channel(local)) {
		/* We're currently on operating channel. */
513
		if (next_chan == local->oper_channel)
514 515 516 517 518 519 520 521 522
			/* We don't need to move off of operating channel. */
			local->next_scan_state = SCAN_SET_CHANNEL;
		else
			/*
			 * We do need to leave operating channel, as next
			 * scan is somewhere else.
			 */
			local->next_scan_state = SCAN_LEAVE_OPER_CHANNEL;
	} else {
523 524
		/*
		 * we're currently scanning a different channel, let's
525 526 527 528 529 530 531 532 533 534 535 536
		 * see if we can scan another channel without interfering
		 * with the current traffic situation.
		 *
		 * Since we don't know if the AP has pending frames for us
		 * we can only check for our tx queues and use the current
		 * pm_qos requirements for rx. Hence, if no tx traffic occurs
		 * at all we will scan as many channels in a row as the pm_qos
		 * latency allows us to. Additionally we also check for the
		 * currently negotiated listen interval to prevent losing
		 * frames unnecessarily.
		 *
		 * Otherwise switch back to the operating channel.
537
		 */
538 539 540 541

		bad_latency = time_after(jiffies +
				ieee80211_scan_get_channel_time(next_chan),
				local->leave_oper_channel_time +
542
				usecs_to_jiffies(pm_qos_request(PM_QOS_NETWORK_LATENCY)));
543 544 545 546 547 548 549 550 551

		listen_int_exceeded = time_after(jiffies +
				ieee80211_scan_get_channel_time(next_chan),
				local->leave_oper_channel_time +
				usecs_to_jiffies(min_beacon_int * 1024) *
				local->hw.conf.listen_interval);

		if (associated && ( !tx_empty || bad_latency ||
		    listen_int_exceeded))
552
			local->next_scan_state = SCAN_ENTER_OPER_CHANNEL;
553
		else
554
			local->next_scan_state = SCAN_SET_CHANNEL;
555 556
	}

557 558 559
	*next_delay = 0;
}

560 561 562
static void ieee80211_scan_state_leave_oper_channel(struct ieee80211_local *local,
						    unsigned long *next_delay)
{
563 564 565 566
	/* PS will already be in off-channel mode,
	 * we do that once at the beginning of scanning.
	 */
	ieee80211_offchannel_stop_vifs(local, false);
567

568 569 570 571 572 573 574 575 576
	/*
	 * What if the nullfunc frames didn't arrive?
	 */
	drv_flush(local, false);
	if (local->ops->flush)
		*next_delay = 0;
	else
		*next_delay = HZ / 10;

577 578 579
	/* remember when we left the operating channel */
	local->leave_oper_channel_time = jiffies;

580
	/* advance to the next channel to be scanned */
581
	local->next_scan_state = SCAN_SET_CHANNEL;
582 583 584 585 586 587 588
}

static void ieee80211_scan_state_enter_oper_channel(struct ieee80211_local *local,
						    unsigned long *next_delay)
{
	/* switch back to the operating channel */
	local->scan_channel = NULL;
589 590
	if (!ieee80211_cfg_on_oper_channel(local))
		ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_CHANNEL);
591 592

	/*
593 594 595
	 * Re-enable vifs and beaconing.  Leave PS
	 * in off-channel state..will put that back
	 * on-channel at the end of scanning.
596
	 */
597
	ieee80211_offchannel_return(local, true, false);
598 599

	*next_delay = HZ / 5;
600
	local->next_scan_state = SCAN_DECISION;
601 602
}

603 604 605 606 607 608
static void ieee80211_scan_state_set_channel(struct ieee80211_local *local,
					     unsigned long *next_delay)
{
	int skip;
	struct ieee80211_channel *chan;

H
Helmut Schaa 已提交
609 610 611
	skip = 0;
	chan = local->scan_req->channels[local->scan_channel_idx];

J
Johannes Berg 已提交
612
	local->scan_channel = chan;
613 614

	/* Only call hw-config if we really need to change channels. */
615
	if (chan != local->hw.conf.channel)
616 617
		if (ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_CHANNEL))
			skip = 1;
H
Helmut Schaa 已提交
618 619 620 621

	/* advance state machine to next channel/band */
	local->scan_channel_idx++;

622 623 624
	if (skip) {
		/* if we skip this channel return to the decision state */
		local->next_scan_state = SCAN_DECISION;
625
		return;
626
	}
H
Helmut Schaa 已提交
627 628 629 630 631 632 633 634 635 636 637 638 639 640

	/*
	 * Probe delay is used to update the NAV, cf. 11.1.3.2.2
	 * (which unfortunately doesn't say _why_ step a) is done,
	 * but it waits for the probe delay or until a frame is
	 * received - and the received frame would update the NAV).
	 * For now, we do not support waiting until a frame is
	 * received.
	 *
	 * In any case, it is not necessary for a passive scan.
	 */
	if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN ||
	    !local->scan_req->n_ssids) {
		*next_delay = IEEE80211_PASSIVE_CHANNEL_TIME;
641
		local->next_scan_state = SCAN_DECISION;
642
		return;
H
Helmut Schaa 已提交
643 644
	}

645
	/* active scan, send probes */
H
Helmut Schaa 已提交
646
	*next_delay = IEEE80211_PROBE_DELAY;
647
	local->next_scan_state = SCAN_SEND_PROBE;
H
Helmut Schaa 已提交
648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667
}

static void ieee80211_scan_state_send_probe(struct ieee80211_local *local,
					    unsigned long *next_delay)
{
	int i;
	struct ieee80211_sub_if_data *sdata = local->scan_sdata;

	for (i = 0; i < local->scan_req->n_ssids; i++)
		ieee80211_send_probe_req(
			sdata, NULL,
			local->scan_req->ssids[i].ssid,
			local->scan_req->ssids[i].ssid_len,
			local->scan_req->ie, local->scan_req->ie_len);

	/*
	 * After sending probe requests, wait for probe responses
	 * on the channel.
	 */
	*next_delay = IEEE80211_CHANNEL_TIME;
668
	local->next_scan_state = SCAN_DECISION;
H
Helmut Schaa 已提交
669 670
}

671
void ieee80211_scan_work(struct work_struct *work)
672 673 674
{
	struct ieee80211_local *local =
		container_of(work, struct ieee80211_local, scan_work.work);
675
	struct ieee80211_sub_if_data *sdata;
676
	unsigned long next_delay = 0;
677
	bool aborted, hw_scan;
678

679
	mutex_lock(&local->mtx);
680

681 682
	sdata = local->scan_sdata;

683
	if (test_and_clear_bit(SCAN_COMPLETED, &local->scanning)) {
684
		aborted = test_and_clear_bit(SCAN_ABORTED, &local->scanning);
685
		goto out_complete;
686 687
	}

688 689
	if (!sdata || !local->scan_req)
		goto out;
690

691
	if (local->scan_req && !local->scanning) {
692 693 694 695
		struct cfg80211_scan_request *req = local->scan_req;
		int rc;

		local->scan_req = NULL;
696
		local->scan_sdata = NULL;
697 698

		rc = __ieee80211_start_scan(sdata, req);
699
		if (rc) {
700 701
			/* need to complete scan in cfg80211 */
			local->scan_req = req;
702 703 704 705
			aborted = true;
			goto out_complete;
		} else
			goto out;
706 707
	}

708 709 710
	/*
	 * Avoid re-scheduling when the sdata is going away.
	 */
711
	if (!ieee80211_sdata_running(sdata)) {
712 713
		aborted = true;
		goto out_complete;
714
	}
715

716 717 718 719 720
	/*
	 * as long as no delay is required advance immediately
	 * without scheduling a new work
	 */
	do {
721 722 723 724 725
		if (!ieee80211_sdata_running(sdata)) {
			aborted = true;
			goto out_complete;
		}

726
		switch (local->next_scan_state) {
727
		case SCAN_DECISION:
728 729 730 731 732 733
			/* if no more bands/channels left, complete scan */
			if (local->scan_channel_idx >= local->scan_req->n_channels) {
				aborted = false;
				goto out_complete;
			}
			ieee80211_scan_state_decision(local, &next_delay);
734
			break;
735 736 737
		case SCAN_SET_CHANNEL:
			ieee80211_scan_state_set_channel(local, &next_delay);
			break;
738 739 740
		case SCAN_SEND_PROBE:
			ieee80211_scan_state_send_probe(local, &next_delay);
			break;
741 742 743 744 745 746
		case SCAN_LEAVE_OPER_CHANNEL:
			ieee80211_scan_state_leave_oper_channel(local, &next_delay);
			break;
		case SCAN_ENTER_OPER_CHANNEL:
			ieee80211_scan_state_enter_oper_channel(local, &next_delay);
			break;
747 748
		}
	} while (next_delay == 0);
749

750
	ieee80211_queue_delayed_work(&local->hw, &local->scan_work, next_delay);
751
	goto out;
752 753

out_complete:
754
	hw_scan = test_bit(SCAN_HW_SCANNING, &local->scanning);
755
	__ieee80211_scan_completed(&local->hw, aborted, hw_scan);
756 757
out:
	mutex_unlock(&local->mtx);
758 759
}

760 761
int ieee80211_request_scan(struct ieee80211_sub_if_data *sdata,
			   struct cfg80211_scan_request *req)
762
{
763
	int res;
764

765
	mutex_lock(&sdata->local->mtx);
766
	res = __ieee80211_start_scan(sdata, req);
767
	mutex_unlock(&sdata->local->mtx);
768

769
	return res;
770 771
}

772
int ieee80211_request_internal_scan(struct ieee80211_sub_if_data *sdata,
J
Johannes Berg 已提交
773 774
				    const u8 *ssid, u8 ssid_len,
				    struct ieee80211_channel *chan)
775 776
{
	struct ieee80211_local *local = sdata->local;
777
	int ret = -EBUSY;
778
	enum ieee80211_band band;
779

780
	mutex_lock(&local->mtx);
781

782 783 784
	/* busy scanning */
	if (local->scan_req)
		goto unlock;
J
Johannes Berg 已提交
785

J
Johannes Berg 已提交
786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809
	/* fill internal scan request */
	if (!chan) {
		int i, nchan = 0;

		for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
			if (!local->hw.wiphy->bands[band])
				continue;
			for (i = 0;
			     i < local->hw.wiphy->bands[band]->n_channels;
			     i++) {
				local->int_scan_req->channels[nchan] =
				    &local->hw.wiphy->bands[band]->channels[i];
				nchan++;
			}
		}

		local->int_scan_req->n_channels = nchan;
	} else {
		local->int_scan_req->channels[0] = chan;
		local->int_scan_req->n_channels = 1;
	}

	local->int_scan_req->ssids = &local->scan_ssid;
	local->int_scan_req->n_ssids = 1;
810 811
	memcpy(local->int_scan_req->ssids[0].ssid, ssid, IEEE80211_MAX_SSID_LEN);
	local->int_scan_req->ssids[0].ssid_len = ssid_len;
J
Johannes Berg 已提交
812

813
	ret = __ieee80211_start_scan(sdata, sdata->local->int_scan_req);
814
 unlock:
815
	mutex_unlock(&local->mtx);
816
	return ret;
817
}
818

819 820 821
/*
 * Only call this function when a scan can't be queued -- under RTNL.
 */
822 823 824
void ieee80211_scan_cancel(struct ieee80211_local *local)
{
	/*
825
	 * We are canceling software scan, or deferred scan that was not
826 827 828 829 830 831 832 833 834 835 836
	 * yet really started (see __ieee80211_start_scan ).
	 *
	 * Regarding hardware scan:
	 * - we can not call  __ieee80211_scan_completed() as when
	 *   SCAN_HW_SCANNING bit is set this function change
	 *   local->hw_scan_req to operate on 5G band, what race with
	 *   driver which can use local->hw_scan_req
	 *
	 * - we can not cancel scan_work since driver can schedule it
	 *   by ieee80211_scan_completed(..., true) to finish scan
	 *
837 838 839
	 * Hence we only call the cancel_hw_scan() callback, but the low-level
	 * driver is still responsible for calling ieee80211_scan_completed()
	 * after the scan was completed/aborted.
840
	 */
841

842
	mutex_lock(&local->mtx);
843 844 845 846 847 848 849
	if (!local->scan_req)
		goto out;

	if (test_bit(SCAN_HW_SCANNING, &local->scanning)) {
		if (local->ops->cancel_hw_scan)
			drv_cancel_hw_scan(local, local->scan_sdata);
		goto out;
850
	}
851 852 853 854 855 856 857 858 859 860

	/*
	 * If the work is currently running, it must be blocked on
	 * the mutex, but we'll set scan_sdata = NULL and it'll
	 * simply exit once it acquires the mutex.
	 */
	cancel_delayed_work(&local->scan_work);
	/* and clean up */
	__ieee80211_scan_completed(&local->hw, true, false);
out:
861
	mutex_unlock(&local->mtx);
862
}
863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913

int ieee80211_request_sched_scan_start(struct ieee80211_sub_if_data *sdata,
				       struct cfg80211_sched_scan_request *req)
{
	struct ieee80211_local *local = sdata->local;
	int ret, i;

	mutex_lock(&sdata->local->mtx);

	if (local->sched_scanning) {
		ret = -EBUSY;
		goto out;
	}

	if (!local->ops->sched_scan_start) {
		ret = -ENOTSUPP;
		goto out;
	}

	for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
		local->sched_scan_ies.ie[i] = kzalloc(2 +
						      IEEE80211_MAX_SSID_LEN +
						      local->scan_ies_len,
						      GFP_KERNEL);
		if (!local->sched_scan_ies.ie[i]) {
			ret = -ENOMEM;
			goto out_free;
		}

		local->sched_scan_ies.len[i] =
			ieee80211_build_preq_ies(local,
						 local->sched_scan_ies.ie[i],
						 req->ie, req->ie_len, i,
						 (u32) -1, 0);
	}

	ret = drv_sched_scan_start(local, sdata, req,
				   &local->sched_scan_ies);
	if (ret == 0) {
		local->sched_scanning = true;
		goto out;
	}

out_free:
	while (i > 0)
		kfree(local->sched_scan_ies.ie[--i]);
out:
	mutex_unlock(&sdata->local->mtx);
	return ret;
}

914
int ieee80211_request_sched_scan_stop(struct ieee80211_sub_if_data *sdata)
915 916 917 918 919 920 921 922 923 924 925 926 927 928 929
{
	struct ieee80211_local *local = sdata->local;
	int ret = 0, i;

	mutex_lock(&sdata->local->mtx);

	if (!local->ops->sched_scan_stop) {
		ret = -ENOTSUPP;
		goto out;
	}

	if (local->sched_scanning) {
		for (i = 0; i < IEEE80211_NUM_BANDS; i++)
			kfree(local->sched_scan_ies.ie[i]);

930
		drv_sched_scan_stop(local, sdata);
931 932 933 934 935 936 937 938 939 940 941 942 943 944 945 946 947 948
		local->sched_scanning = false;
	}
out:
	mutex_unlock(&sdata->local->mtx);

	return ret;
}

void ieee80211_sched_scan_results(struct ieee80211_hw *hw)
{
	struct ieee80211_local *local = hw_to_local(hw);

	trace_api_sched_scan_results(local);

	cfg80211_sched_scan_results(hw->wiphy);
}
EXPORT_SYMBOL(ieee80211_sched_scan_results);

949 950 951 952 953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972
void ieee80211_sched_scan_stopped_work(struct work_struct *work)
{
	struct ieee80211_local *local =
		container_of(work, struct ieee80211_local,
			     sched_scan_stopped_work);
	int i;

	mutex_lock(&local->mtx);

	if (!local->sched_scanning) {
		mutex_unlock(&local->mtx);
		return;
	}

	for (i = 0; i < IEEE80211_NUM_BANDS; i++)
		kfree(local->sched_scan_ies.ie[i]);

	local->sched_scanning = false;

	mutex_unlock(&local->mtx);

	cfg80211_sched_scan_stopped(local->hw.wiphy);
}

973 974 975 976 977 978
void ieee80211_sched_scan_stopped(struct ieee80211_hw *hw)
{
	struct ieee80211_local *local = hw_to_local(hw);

	trace_api_sched_scan_stopped(local);

979
	ieee80211_queue_work(&local->hw, &local->sched_scan_stopped_work);
980 981
}
EXPORT_SYMBOL(ieee80211_sched_scan_stopped);